I am still trying to setup a clean guest WLAN which is directly routed via external firewall into the www.
So I set up as follows:
at aruba 7005:
Interface IP Address / IP Netmask Admin Protocol VRRP-IP
vlan 1 192.168.0.254 / 255.255.254.0 up up
vlan 100 172.16.0.2 / 255.255.255.0 up up
C 192.168.0.0/23 is directly connected, VLAN1
C 172.16.0.0/24 is directly connected, VLAN100
VLAN Description Ports AAA Profile Option-82
---- ----------- ----- ----------- ---------
1 Default GE0/0/0-0/2 Pc0-7 N/A Disabled
100 VLAN0100 GE0/0/3 N/A Disabled
DHCP-Helper ist set to 172.16.0.1 = DHCP on external firewall for VLAN100 ONLY.
created a guest WLAN and bound it to VLAN 100.
At external firewall:
created an virtual eth ("eth3:1") with 172.16.0.1
created a guest network 172.16.0.0/24
created a DHCP-Pool in this range
created a static route for 172.16.0.0/24 => 172.16.0.2=aruba
When I do now plugin the cable between eth3 on aruba and the DMZ-switch (where the external firewall resides) happens the following:
Guest-WLAN is working as expected, but:
Internal WLAN is broken immediately.
So I configured VLAN at the DMZ switch (HP 2900al)
added VLAN 100
Port 1 (=aruba eth3) set to:
default vlan (=1): Forbid
VLAN 100: Tagged
Port 24 (=firewall)
default vlan (=1): Untagged
VLAN 100: Tagged
When I now do plugin that named cable internal WLAN stays fine - but Guest-WLAN stops working.
For not always trying to connect to Guest-WLAN and obtaining an IP by DHCP I am debugging with static client IP setting and trying to ping aruba vs. firewall by wire - but so far with no luck.
Where is my fault in this?
Any help would be appreciated- I even worked as a painter for better understandig.

Thank you in advance- F.One